You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The command you outlined in this documentation for creating a cosmosDB sql role assignment for a service principal does not work in Azure CLI. az cosmosdb sql role assignment create --account-name $ACCOUNT_NAME --resource-group $RESOURCE_GROUP_NAME --scope "/" --principal-id $PRINCIPAL_ID --role-definition-id $READ_WRITE_DEFINITION_ROLE_ID
Currently, I not only need the correct Object ID but also needed to supply an extra flag --principal-type ServicePrincipal" in order to make the command work, like so: az cosmosdb sql role assignment create --account-name $ACCOUNT_NAME --resource-group $RESOURCE_GROUP_NAME --scope "/" --principal-id $PRINCIPAL_ID --role-definition-id $READ_WRITE_DEFINITION_ROLE_ID --principal-type "ServicePrincipal"
Otherwise, I got the following error:
Code: BadRequest
Message: The provided principal ID [REDACTED] was found to be of an unsupported type : [Application]
ActivityId: [REDACTED], Microsoft.Azure.Documents.Common/2.14.0, Microsoft.Azure.Documents.Common/2.14.0, Microsoft.Azure.Documents.Common/2.14.0, Microsoft.Azure.Documents.Common/2.14.0, Microsoft.Azure.Documents.Common/2.14.0, Microsoft.Azure.Documents.Common/2.14.0
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
ID: aba612b3-f404-11b2-45d9-6e10f1fbf11d
Version Independent ID: 86ccb46e-5ebd-50a4-a911-2ac83c8a41f4
Hi @UnMorrer
Thank you for bringing this to our attention! We've initiated a pull request (PR) to address this issue. Once the author reviews the changes, they will be merged, and the updates should go live shortly. Your diligence is much appreciated!
Dear Microsoft team,
The command you outlined in this documentation for creating a cosmosDB sql role assignment for a service principal does not work in Azure CLI.
az cosmosdb sql role assignment create --account-name $ACCOUNT_NAME --resource-group $RESOURCE_GROUP_NAME --scope "/" --principal-id $PRINCIPAL_ID --role-definition-id $READ_WRITE_DEFINITION_ROLE_ID
Currently, I not only need the correct Object ID but also needed to supply an extra flag --principal-type ServicePrincipal" in order to make the command work, like so:
az cosmosdb sql role assignment create --account-name $ACCOUNT_NAME --resource-group $RESOURCE_GROUP_NAME --scope "/" --principal-id $PRINCIPAL_ID --role-definition-id $READ_WRITE_DEFINITION_ROLE_ID --principal-type "ServicePrincipal"
Otherwise, I got the following error:
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
The text was updated successfully, but these errors were encountered: